<div dir="ltr"><div dir="ltr">hi,<div><br></div><div>Peter has already given the direct thing to look at but I'd recommend reading this nice resource as it covers that issue and more:<br><br></div><div><a href="https://mimoto.co.uk/sp/security/identity/infrastructure/2023/05/09/harden-shibboleth-sp.html">https://mimoto.co.uk/sp/security/identity/infrastructure/2023/05/09/harden-shibboleth-sp.html</a></div></div><div><br></div>it was also covered in a security bulletin to some members of the global research and education federations<div>e.g.</div><div><a href="https://www.ukfederation.org.uk/content/News/2023-01-10-Shibboleth-SP-Open-Redirect">https://www.ukfederation.org.uk/content/News/2023-01-10-Shibboleth-SP-Open-Redirect</a></div><div><a href="https://support.aaf.edu.au/support/solutions/articles/19000130194-is-your-sp-vulnerable-to-being-used-as-an-open-redirector">https://support.aaf.edu.au/support/solutions/articles/19000130194-is-your-sp-vulnerable-to-being-used-as-an-open-redirector</a><br><br><div class="gmail_quote"><div class="gmail_attr">regards</div><div class="gmail_attr"><br></div><div class="gmail_attr">alan</div></div></div></div>